CVE-2026-3241
Received Received - Intake
Stored XSS in Concrete CMS Legacy Form Allows Persistent Injection

Publication date: 2026-03-04

Last updated on: 2026-03-04

Assigner: ConcreteCMS

Description
In Concrete CMS below version 9.4.8, aΒ stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript payload into the options of a multiple-choice question (Checkbox List, Radio Buttons, or Select Box). This payload is then executed in the browser of any user who views the page containing the form.Β The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vectorΒ CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. ThanksΒ M3dium for reporting.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-04
Last Modified
2026-03-04
Generated
2026-06-16
AI Q&A
2026-03-04
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms to 9.4.8 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) issue found in Concrete CMS versions below 9.4.8, specifically in the "Legacy Form" block.

An authenticated user who has permissions to create or edit forms, such as a rogue administrator, can inject persistent JavaScript code into the options of multiple-choice questions like Checkbox List, Radio Buttons, or Select Box.

When other users view the page containing the affected form, the injected JavaScript payload executes in their browsers, potentially leading to malicious actions.

Impact Analysis

This vulnerability can impact you by allowing an attacker with form editing permissions to execute malicious JavaScript in the browsers of users who view the compromised form.

Such execution can lead to unauthorized actions like stealing session cookies, defacing content, or performing actions on behalf of the victim user.

Because the attacker needs authenticated access with form editing rights, the risk is somewhat limited to insider threats or compromised administrator accounts.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3241. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart